Sometimes, I get embarrassed by what I experience here on HN. The gang up, the unnecessary pride.
To those saying RIP, Telegram will succeed. Without using it (I use a Blackberry), it looks to be top two of the chat apps when you combine usability/security. I will download it once I get an Android phone in January.
I will not wish failure on anyone that is confident in his product. Of course they could have shown more humility but it he face of "take downs" on all sides especially the ones sponsored or initiated by the Whispersystem/Texsecure chaps, I do not see why they should have bowed down to be crushed.
Considering the type of responses given by Pavel Durov, I am almost certain he would have been much more humble if his attackers toned it down a notch.
To the person that found a flaw, kudos to you on doing something and not spending all your time doing take downs of telegram on HN threads and blogs.
Pavel, I am hopeful that you will reward the chap even though the discovery was not within the "guidelines". it is all about the spirit of the competition.
As for the TextSecure/WhisperSystems guys, stop being like the politicians we hate who campaign by slinging mud on opponents instead of selling their stuff. Focus on selling the TextSecure app and not looking to takeout anyone who has a different approach.
PS: I have no relationship with either party. I am a neutral observer that has his own opinions.
To those saying RIP, Telegram will succeed. Without using it (I use a Blackberry), it looks to be top two of the chat apps when you combine usability/security. I will download it once I get an Android phone in January.
But it is not secure! That's the entire point.
Never mind "not secure against a well funded government agency", it's not secure against other attackers.
There are lots of usable chat apps that do not give you the illusion of security.
and not looking to takeout anyone who has a different approach.
You seem to be mistaken about why they do this. It's nothing to do with pushing their app or their approach. They'd welcome good well-formed apps to compete with them. But when they see an app that claims to be secure they have an ethical duty to let people know if it is obviously not secure.
Most people are not bashing just for the sake of bashing. Some people need good cryptography software to avoid imprisonment, or torture, or state-killing. This isn't about stopping someone's teen-angsty poetry from being discovered by a sibling, it's about protecting political dissidents from an oppressive regime. In that context pointing out that a software is broken is not mindless bashing, it is a crucial part of the cryptography process.
(I'll accept that a few people are missing the mark with their criticisms.)
Pointing out flawed crypto software is part of a long tradition going back many years. It's part of the culture. Most cryptographer will start by analysing other software and finding flaws before implementing their own software.
Most people are not bashing just for the sake of bashing. Some people need good cryptography software to avoid imprisonment, or torture, or state-killing. This isn't about stopping someone's teen-angsty poetry from being discovered by a sibling, it's about protecting political dissidents from an oppressive regime. In that context pointing out that a software is broken is not mindless bashing, it is a crucial part of the cryptography process.
I like your commentary it is level headed and explains the position of the non biased "other side".
I think the conflicted position of the lead bashers did not help their position. It would have been much more useful for a neutral party to do a comparative analysis and stated the pros and cons of each side.
As for me and most normal users, the security we need is not from NSA type of snooping but from mid level risks. There may be some sacrifices that may have to be made. Just like the position Ubuntu plays where Linux distros are concerned
For people like Snowden, Greenwald and others with NSA level adversaries, I do not expect them to rely on any third party application at all.
Now your argument may be that they have created stuff for sexting teens and claimed to be good enough for Snowden. In that case, I would argue that it could have been pointed out that in a different and perhaps more polite way.
I would worry about anyone who has created any crypto tool who is not over confident in his product. I will also expect the person to be receptive to constructive feedback NOT "leave your product and join us" or "This is shit because no noted crypto person is on your team"
I remember when cperciva that built Tarsnap, an online "backup for paranoid users" launched, he was rather confident in his product and I did not see any intense bashing of him. As expected,there have been bugs in his system and he has fixed them as they have arisen.
We should help things grow right here on HN not hope for things to fail if they do not support the view of the crowd.
It would have been much more useful for a neutral party to do a comparative analysis and stated the pros and cons of each side.
And what would this neutral party be?
As for me and most normal users, the security we need is not from NSA type of snooping but from mid level risks. There may be some sacrifices that may have to be made. Just like the position Ubuntu plays where Linux distros are concerned
You make it sound as if having government-grade encryption was very hard or very costly but that's obviously not the case, there are many open encryption standard who wouldn't have had the kind of issues Telegram has. Do you want to start a new contest targeting a properly configured openSSH for instance? There is no need for tradeoff there.
I remember when cperciva that built Tarsnap, an online "backup for paranoid users" launched, he was rather confident in his product and I did not see any intense bashing of him. As expected,there have been bugs in his system and he has fixed them as they have arisen.
Colin Percival has credentials and experience in the cryptoworld. When he makes "new" crypto like scrypt he publishes it and it's been thoroughly reviewed. It also has distinct advantages over previous technologies, it's not just new for the sake of being new.
Crypto is serious business, people can get hurt. Toying with crypto, proposing new ideas is of course to be encouraged, but be humble about it and listen to the feedback. Actually, this last part is true for everything.
Colin Percival has credentials and experience in the cryptoworld. When he makes "new" crypto like scrypt he publishes it and it's been thoroughly reviewed. It also has distinct advantages over previous technologies, it's not just new for the sake of being new.
He also, AFAICR, did not appear over confident, he was clear in delineating what his application does and does not protect against, and what his goals are (that is one reason why he deserves these crypto credentials).
He published his entire source code.
And when he launched a contest, it was in the form of a bug bounty, he accepted any kind of bugs (up to and including spelling errors in his code comments :) ).
Completely disagree. It was just a week or two before Snowden came out that New York Times was praising Skype for how "secure" it is, even against government snooping. The poor souls thought Skype was still P2P, when that stopped being true many years before. The NYT journalists were also probably using Skype to talk to their sources, thinking they are secure. That's why it's so important to have such reviews of these apps - especially if they're a more "mainstream app", and there's a potential for hundreds of millions of people to use it. If we can get hundreds of millions of people to use end-to-end encrypted communication, why not do it properly, and give them half-baked secure apps to use instead?
Also all "secure apps" that aren't fully open source should be considered insecure by default. No compromises. Whatsapp, Snapchat, Hangouts, Skype, they're all insecure and you can't rely on them for keeping your communications private.
It would have been much more useful for a neutral party to do a comparative analysis and stated the pros and cons of each side.
Like, say, tptacek, who is not in the "instant messenger" business, who is in the security audit business, and whose comments here on the technical details of the Telegram protocol have been absolutely damning? See https://news.ycombinator.com/item?id=6941934 for example.
I wholeheartedly disagree. For any user, the security we need is prevent eavesdropping & data mining by our governments. They use it to profile us, to find thoughtcrime and to secure their standing in a surveillance society. We should not let that happen.
Do you live or work in a building that has windows on the ground floor?
Who made your doors? What specification were your doors built to? Who made your door locks? What specification were they built to? Who has authority to cut keys to those locks? How do you know?
If you truly are as worried by governments as you claim why are you not fortifying your home?
Using good crypto is fortifying your home. People could easily learn information that could help them secretly enter my home if they could monitor my communications.
As for me and most normal users, the security we need is not from NSA type of snooping but from mid level risks.
Most users, disregarding the government for the moment, don't need encryption full stop. They don't send anything commercially sensitive that an attacker's going to be interested enough in to try to intercept their messages.
The use of encryption presupposes a motivated threat, and it's not clear to me that the NSA is significantly more powerful than other adversaries in that area. They've more computing power, more political power, they can buy zero day exploits. They probably even have some very smart people, who can find flaws faster than the attackers in civ-space. But speed isn't required, only persistence; motivation, interest. Which is, after all, what we're supposing in the first place if someone's going to go to the trouble of intercepting your messages.
It's not clear to me that unless your goal is 'make something that the NSA can't break into', you're going to make something that a well motivated attacker can't break into either. And this stuff only has to be broken once, then they'll just sell or share the attack. The conflict is asymmetrical.
Your argument seems to be posited on the idea that there will be no attacker; no-one anywhere, ever; sufficiently motivated to breach the protocol. And I find that highly questionable, given that a flaw has already been found - and with far lower levels of incentive than will be present if the system is widely deployed and used to protect valuable information.
Most users, disregarding the government for the moment, don't need encryption full stop.
You've no idea what you're talking about. Please stop spreading such bullshit around; other people might fall for it!
Fireship is an app that allows you to hijack the account of any user on the same Wi-Fi network as you are, if the network is not encrypted, and the user used a non-encrypted connection to the website. Facebook, Google, Twitter and Flicker were all susceptible to such attacks before the advent of this tool; afterwards, they fixed it by using https by default.
Do you want random strangers to have full access to your Facebook account? No? Then you should realize that most people do need encryption full stop.
Also, only very powerful attackers can hack https encryption (they need either access to your laptop (hardware access, or a zero-day exploit), or access to the website (e.g. court warrant, or coercing a certificate authority)).
We were having a discussion about Telegram and similar uses of encryption, a discussion where I specifically responded to a remark on the strength required of Telegram-style encryption. I would hope that most people are capable of interpreting the context of a remark - especially embedded in paragraphs that expand on it. Rather than, 'fall[ing] for it!'
-sigh-
Beyond that I'm not going to engage with you any further, on this or any other point. You strike me as a bully, restrained where you are simply by the absence of an excuse rather than the presence of decency. As such, I've no interest in associating with you.
The wishing of failure isn't great, my personal wish would be for the Telegram people to learn the errors of their ways rather than necessarily completely fail.
Overstated claims of privacy could get people killed if they trust them so it is a serious issue.
Telegram have an arrogance that is inappropriate in security/crypto protocol development. Most crypto protocols, even those developed by experts initially have problems (at the protocol design level even ignoring the implementation bugs) which is why even experts only come up with new ones when there isn't any existing one with the required properties and even then reuse as much existing battle tested technology as possible and submit it to worldwide evaluation tentatively and nervously.
The competition was set up in a way that clearly excluded most threats and was either another sign that Telegram didn't understand most of the threat space OR that they did and wanted to rig the competition to be unwinnable while claiming that it validated the security in some way.
So at least until yesterday Telegram were arrogant and either completely clueless about crypto protocols or PR bullshitters with some clue and a poor protocol. They need to get a clue AND drop the arrogance to get support from me.
Until these things happen Telegram are a danger that people should be warned about and not regard as secure.
I am also a neutral party with no relationship with either party.
he would have been much more humble if his attackers toned
it down a notch.
Conversely you can argue that the 'attackers' would have toned it down a notch if Telegram had been more humble and receptive of the comments. The initial comments were quite civil and they were just dismissed.
looking to takeout anyone who has a different approach.
It's not just a 'different' approach. It's an approach that's likely to be dangerously flawed, as just demonstrated. It's unfortunate that the people involved have a 'rival' product and they could do with pointing to it a bit less, but it doesn't make any of the criticisms less valid. Painting them as 'politics' is just slander.
This trend of ignoring the content because of the tone is pervasive and troubling. I understand that tone matters in regards to reception, but in this place i assume we all, grammar nazis and privilege checkers alike, choose to asses the technical aspects of comments and largely disregard the "gift wrap". In this situation, the problem with Telegram is their words right big checks their work cannot cash. The TextSecure chaps are defending their turf viciously, but i have yet to see one of them make a personal assessment as the predicate for their assault. I have been following it very closely, comment wise, and all it has really been is long winded explanations (on the TextSecure side) of why the Telegram contest was a sham (it was) and why TextSecure is better (i have no way to judge). On the other side (Telegram), all i see are pleas to leave the Telegram guys alone, hate toward Moxie et al., and general pseudo-martyr comments about how mean Hacker News is.
Good. Let's be hard to please. This is not [spoiler]fucking[/spoiler] macaroni paintings we are making and using to please mommy. These are the apps we all use to continue our work and edify our lives. I want it to be a gauntlet; i think it is great that people's products are critiqued so meticulously, and i am happy that a competition with such glaring inconsistencies (to whomever wrote the alternate competition explanation...thank you)did not survive for long. As an American, i am so tired of security theater. If something is touted as secure and is not, i want to know about it.
And as for the ridicule, if you obfuscate and misrepresent, you invite a harsh response.
Telegram is making ridiculous claims that have the potential to hurt their customers. They are lying and/or incompetent. They absolutely deserve to be made fun of.
As for the TextSecure/WhisperSystems guys, stop being like the politicians we hate who campaign by slinging mud on opponents instead of selling their stuff.
It's funny that you mention politicians at the end of the post, because as I was reading your posts in this thread, I couldn't help but think you were feeding into the huge cable-newsification of this disagreement. It is what happens when a bunch of lookie-loo viewers want to be involved in the debate but can't keep up on the issues. I struggle to completely follow the tech here but my job occasionally brings me close enough to crypto that if nothing else I understand the huge disparity between the technical discussion and the superficial one at play here.
Attempts to fit this disagreement into the same oblique, non-existent, ideal behavior for a disagreement subverts the ability to productivity disagree and makes behavior worse overall. Your remedy is for them to not disagree. I take it differently. I want them to disagree, but I don't want anyone involved in the disagreement to dishonestly play to the masses. But that would involve conceding a point, and what would that do to the bottom line?
Focus on selling the TextSecure app and not looking to takeout anyone who has a different approach.
You mistakenly seem to think that TextSecure exists primarily for profit. It is obvious the aim is good crypto. They're playing a different ball game than Telegraph's freemium model, one where marketplace success doesn't determine if they implemented their crypto right. Promoting _that_ involves explaining why the Telegraph tech is deficient.
Back to the cable news analogy, in a post of yours further down the thread, you bring up what the right level of security is for this app. That's a good question, one moxie (I think) brought up days ago by pointing out they didn't have threat model and tptacek (I think) called them out for using nation-state actors as the adversary in selling the app. They played that card in technical criticism, you bringing it up here for goalpost shifting now that they're starting to look bad and you want to keep driving down the middle of the disagreement.
PS: I have no relationship with either party. I am a neutral observer that has his own opinions.
Oh, I know. You're playing into the US-politics detached observer rote well. You should know that the system adapted to account for that stance years ago. You're getting played as hard as everyone else.
>Pavel, I am hopeful that you will reward the chap even though the discovery was not within the "guidelines". it is all about the spirit of the competition.
The app was far from being a "secure" app. And going by how far they've to promote it as a "secure" app, of course there should be an equal amount of response for why it's not secure (since it isn't!). This is not just about some "guys making an app and being taken down for it". This is serious stuff. They're claiming their security is one of the best in the world, when it couldn't be farther from the truth. Why would you want such an app to be popular and make people think it's actually secure, when it's not?
well, if someone causes you significant lose, will you turn down a norch? That's why we are bashing on them as they are making BS claims about how secure their protocol is.
Comments
This is my first comment on the Telegram bruhaha.
Sometimes, I get embarrassed by what I experience here on HN. The gang up, the unnecessary pride.
To those saying RIP, Telegram will succeed. Without using it (I use a Blackberry), it looks to be top two of the chat apps when you combine usability/security. I will download it once I get an Android phone in January.
I will not wish failure on anyone that is confident in his product. Of course they could have shown more humility but it he face of "take downs" on all sides especially the ones sponsored or initiated by the Whispersystem/Texsecure chaps, I do not see why they should have bowed down to be crushed.
Considering the type of responses given by Pavel Durov, I am almost certain he would have been much more humble if his attackers toned it down a notch.
To the person that found a flaw, kudos to you on doing something and not spending all your time doing take downs of telegram on HN threads and blogs.
Pavel, I am hopeful that you will reward the chap even though the discovery was not within the "guidelines". it is all about the spirit of the competition.
As for the TextSecure/WhisperSystems guys, stop being like the politicians we hate who campaign by slinging mud on opponents instead of selling their stuff. Focus on selling the TextSecure app and not looking to takeout anyone who has a different approach.
PS: I have no relationship with either party. I am a neutral observer that has his own opinions.
But it is not secure! That's the entire point.
Never mind "not secure against a well funded government agency", it's not secure against other attackers.
There are lots of usable chat apps that do not give you the illusion of security.
You seem to be mistaken about why they do this. It's nothing to do with pushing their app or their approach. They'd welcome good well-formed apps to compete with them. But when they see an app that claims to be secure they have an ethical duty to let people know if it is obviously not secure.
Most people are not bashing just for the sake of bashing. Some people need good cryptography software to avoid imprisonment, or torture, or state-killing. This isn't about stopping someone's teen-angsty poetry from being discovered by a sibling, it's about protecting political dissidents from an oppressive regime. In that context pointing out that a software is broken is not mindless bashing, it is a crucial part of the cryptography process.
(I'll accept that a few people are missing the mark with their criticisms.)
Pointing out flawed crypto software is part of a long tradition going back many years. It's part of the culture. Most cryptographer will start by analysing other software and finding flaws before implementing their own software.
Most people are not bashing just for the sake of bashing. Some people need good cryptography software to avoid imprisonment, or torture, or state-killing. This isn't about stopping someone's teen-angsty poetry from being discovered by a sibling, it's about protecting political dissidents from an oppressive regime. In that context pointing out that a software is broken is not mindless bashing, it is a crucial part of the cryptography process.
I like your commentary it is level headed and explains the position of the non biased "other side".
I think the conflicted position of the lead bashers did not help their position. It would have been much more useful for a neutral party to do a comparative analysis and stated the pros and cons of each side.
As for me and most normal users, the security we need is not from NSA type of snooping but from mid level risks. There may be some sacrifices that may have to be made. Just like the position Ubuntu plays where Linux distros are concerned
For people like Snowden, Greenwald and others with NSA level adversaries, I do not expect them to rely on any third party application at all.
Now your argument may be that they have created stuff for sexting teens and claimed to be good enough for Snowden. In that case, I would argue that it could have been pointed out that in a different and perhaps more polite way.
I would worry about anyone who has created any crypto tool who is not over confident in his product. I will also expect the person to be receptive to constructive feedback NOT "leave your product and join us" or "This is shit because no noted crypto person is on your team"
I remember when cperciva that built Tarsnap, an online "backup for paranoid users" launched, he was rather confident in his product and I did not see any intense bashing of him. As expected,there have been bugs in his system and he has fixed them as they have arisen.
We should help things grow right here on HN not hope for things to fail if they do not support the view of the crowd.
I don't think your arguments make a lot of sense:
And what would this neutral party be?
You make it sound as if having government-grade encryption was very hard or very costly but that's obviously not the case, there are many open encryption standard who wouldn't have had the kind of issues Telegram has. Do you want to start a new contest targeting a properly configured openSSH for instance? There is no need for tradeoff there.
Colin Percival has credentials and experience in the cryptoworld. When he makes "new" crypto like scrypt he publishes it and it's been thoroughly reviewed. It also has distinct advantages over previous technologies, it's not just new for the sake of being new.
Crypto is serious business, people can get hurt. Toying with crypto, proposing new ideas is of course to be encouraged, but be humble about it and listen to the feedback. Actually, this last part is true for everything.
He also, AFAICR, did not appear over confident, he was clear in delineating what his application does and does not protect against, and what his goals are (that is one reason why he deserves these crypto credentials).
He published his entire source code.
And when he launched a contest, it was in the form of a bug bounty, he accepted any kind of bugs (up to and including spelling errors in his code comments :) ).
Completely disagree. It was just a week or two before Snowden came out that New York Times was praising Skype for how "secure" it is, even against government snooping. The poor souls thought Skype was still P2P, when that stopped being true many years before. The NYT journalists were also probably using Skype to talk to their sources, thinking they are secure. That's why it's so important to have such reviews of these apps - especially if they're a more "mainstream app", and there's a potential for hundreds of millions of people to use it. If we can get hundreds of millions of people to use end-to-end encrypted communication, why not do it properly, and give them half-baked secure apps to use instead?
Also all "secure apps" that aren't fully open source should be considered insecure by default. No compromises. Whatsapp, Snapchat, Hangouts, Skype, they're all insecure and you can't rely on them for keeping your communications private.
It would have been much more useful for a neutral party to do a comparative analysis and stated the pros and cons of each side.
Like, say, tptacek, who is not in the "instant messenger" business, who is in the security audit business, and whose comments here on the technical details of the Telegram protocol have been absolutely damning? See https://news.ycombinator.com/item?id=6941934 for example.
I wholeheartedly disagree. For any user, the security we need is prevent eavesdropping & data mining by our governments. They use it to profile us, to find thoughtcrime and to secure their standing in a surveillance society. We should not let that happen.
Do you live or work in a building that has windows on the ground floor?
Who made your doors? What specification were your doors built to? Who made your door locks? What specification were they built to? Who has authority to cut keys to those locks? How do you know?
If you truly are as worried by governments as you claim why are you not fortifying your home?
Using good crypto is fortifying your home. People could easily learn information that could help them secretly enter my home if they could monitor my communications.
Because they do not have omnipresent sensors. That is a completely silly comparison.
Most users, disregarding the government for the moment, don't need encryption full stop. They don't send anything commercially sensitive that an attacker's going to be interested enough in to try to intercept their messages.
The use of encryption presupposes a motivated threat, and it's not clear to me that the NSA is significantly more powerful than other adversaries in that area. They've more computing power, more political power, they can buy zero day exploits. They probably even have some very smart people, who can find flaws faster than the attackers in civ-space. But speed isn't required, only persistence; motivation, interest. Which is, after all, what we're supposing in the first place if someone's going to go to the trouble of intercepting your messages.
It's not clear to me that unless your goal is 'make something that the NSA can't break into', you're going to make something that a well motivated attacker can't break into either. And this stuff only has to be broken once, then they'll just sell or share the attack. The conflict is asymmetrical.
Your argument seems to be posited on the idea that there will be no attacker; no-one anywhere, ever; sufficiently motivated to breach the protocol. And I find that highly questionable, given that a flaw has already been found - and with far lower levels of incentive than will be present if the system is widely deployed and used to protect valuable information.
You've no idea what you're talking about. Please stop spreading such bullshit around; other people might fall for it!
Fireship is an app that allows you to hijack the account of any user on the same Wi-Fi network as you are, if the network is not encrypted, and the user used a non-encrypted connection to the website. Facebook, Google, Twitter and Flicker were all susceptible to such attacks before the advent of this tool; afterwards, they fixed it by using https by default.
Do you want random strangers to have full access to your Facebook account? No? Then you should realize that most people do need encryption full stop.
Also, only very powerful attackers can hack https encryption (they need either access to your laptop (hardware access, or a zero-day exploit), or access to the website (e.g. court warrant, or coercing a certificate authority)).
We were having a discussion about Telegram and similar uses of encryption, a discussion where I specifically responded to a remark on the strength required of Telegram-style encryption. I would hope that most people are capable of interpreting the context of a remark - especially embedded in paragraphs that expand on it. Rather than, 'fall[ing] for it!'
-sigh-
Beyond that I'm not going to engage with you any further, on this or any other point. You strike me as a bully, restrained where you are simply by the absence of an excuse rather than the presence of decency. As such, I've no interest in associating with you.
Yeah, I probably overreacted.
The wishing of failure isn't great, my personal wish would be for the Telegram people to learn the errors of their ways rather than necessarily completely fail.
Overstated claims of privacy could get people killed if they trust them so it is a serious issue.
Telegram have an arrogance that is inappropriate in security/crypto protocol development. Most crypto protocols, even those developed by experts initially have problems (at the protocol design level even ignoring the implementation bugs) which is why even experts only come up with new ones when there isn't any existing one with the required properties and even then reuse as much existing battle tested technology as possible and submit it to worldwide evaluation tentatively and nervously.
The competition was set up in a way that clearly excluded most threats and was either another sign that Telegram didn't understand most of the threat space OR that they did and wanted to rig the competition to be unwinnable while claiming that it validated the security in some way.
So at least until yesterday Telegram were arrogant and either completely clueless about crypto protocols or PR bullshitters with some clue and a poor protocol. They need to get a clue AND drop the arrogance to get support from me.
Until these things happen Telegram are a danger that people should be warned about and not regard as secure.
I am also a neutral party with no relationship with either party.
This trend of ignoring the content because of the tone is pervasive and troubling. I understand that tone matters in regards to reception, but in this place i assume we all, grammar nazis and privilege checkers alike, choose to asses the technical aspects of comments and largely disregard the "gift wrap". In this situation, the problem with Telegram is their words right big checks their work cannot cash. The TextSecure chaps are defending their turf viciously, but i have yet to see one of them make a personal assessment as the predicate for their assault. I have been following it very closely, comment wise, and all it has really been is long winded explanations (on the TextSecure side) of why the Telegram contest was a sham (it was) and why TextSecure is better (i have no way to judge). On the other side (Telegram), all i see are pleas to leave the Telegram guys alone, hate toward Moxie et al., and general pseudo-martyr comments about how mean Hacker News is.
Good. Let's be hard to please. This is not [spoiler]fucking[/spoiler] macaroni paintings we are making and using to please mommy. These are the apps we all use to continue our work and edify our lives. I want it to be a gauntlet; i think it is great that people's products are critiqued so meticulously, and i am happy that a competition with such glaring inconsistencies (to whomever wrote the alternate competition explanation...thank you)did not survive for long. As an American, i am so tired of security theater. If something is touted as secure and is not, i want to know about it.
And as for the ridicule, if you obfuscate and misrepresent, you invite a harsh response.
Telegram is making ridiculous claims that have the potential to hurt their customers. They are lying and/or incompetent. They absolutely deserve to be made fun of.
As for the TextSecure/WhisperSystems guys, stop being like the politicians we hate who campaign by slinging mud on opponents instead of selling their stuff.
It's funny that you mention politicians at the end of the post, because as I was reading your posts in this thread, I couldn't help but think you were feeding into the huge cable-newsification of this disagreement. It is what happens when a bunch of lookie-loo viewers want to be involved in the debate but can't keep up on the issues. I struggle to completely follow the tech here but my job occasionally brings me close enough to crypto that if nothing else I understand the huge disparity between the technical discussion and the superficial one at play here.
Attempts to fit this disagreement into the same oblique, non-existent, ideal behavior for a disagreement subverts the ability to productivity disagree and makes behavior worse overall. Your remedy is for them to not disagree. I take it differently. I want them to disagree, but I don't want anyone involved in the disagreement to dishonestly play to the masses. But that would involve conceding a point, and what would that do to the bottom line?
Focus on selling the TextSecure app and not looking to takeout anyone who has a different approach.
You mistakenly seem to think that TextSecure exists primarily for profit. It is obvious the aim is good crypto. They're playing a different ball game than Telegraph's freemium model, one where marketplace success doesn't determine if they implemented their crypto right. Promoting _that_ involves explaining why the Telegraph tech is deficient.
Back to the cable news analogy, in a post of yours further down the thread, you bring up what the right level of security is for this app. That's a good question, one moxie (I think) brought up days ago by pointing out they didn't have threat model and tptacek (I think) called them out for using nation-state actors as the adversary in selling the app. They played that card in technical criticism, you bringing it up here for goalpost shifting now that they're starting to look bad and you want to keep driving down the middle of the disagreement.
PS: I have no relationship with either party. I am a neutral observer that has his own opinions.
Oh, I know. You're playing into the US-politics detached observer rote well. You should know that the system adapted to account for that stance years ago. You're getting played as hard as everyone else.
>Pavel, I am hopeful that you will reward the chap even though the discovery was not within the "guidelines". it is all about the spirit of the competition.
He does reward the chap—with $100 000: https://vk.com/wall-52630202_7858
I figure it's fair.
Really?
The protocol is bad, this competition protects only the most basic attacks and still was broken in about 5 days.
It's not "unnecessary pride". You have to be really cautios with cryptography. Not use the first thing that has "Secure!" sticker on it.
The app was far from being a "secure" app. And going by how far they've to promote it as a "secure" app, of course there should be an equal amount of response for why it's not secure (since it isn't!). This is not just about some "guys making an app and being taken down for it". This is serious stuff. They're claiming their security is one of the best in the world, when it couldn't be farther from the truth. Why would you want such an app to be popular and make people think it's actually secure, when it's not?
They did give him a reward. Telegram has just posted the translation on twitter. Moved to separate discussion: https://news.ycombinator.com/item?id=6950129
well, if someone causes you significant lose, will you turn down a norch? That's why we are bashing on them as they are making BS claims about how secure their protocol is.